Courseiva
mediumMultiple Choice

FC0-U71 Access control policy Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "effect": "Deny",
  "action": "s3:DeleteObject",
  "resource": "arn:aws:s3:::my-bucket/*",
  "condition": {
    "IpAddress": {
      "aws:SourceIp": "192.0.2.0/24"
    }
  }
}
```

An administrator reviews the following access control policy:

{
  "Rule": {
    "Effect": "Deny",
    "Action": "delete",
    "Resource": "file-server",
    "Condition": {
      "IpAddress": {
        "SourceIp": "192.0.2.0/24"
      }
    }
  }
}

What does it do?

⚠ Common exam trap

Watch out — candidates often confuse a Deny statement for a specific action with a blanket denial of all actions, or they misinterpret the IP condition as applying to all actions instead of only the listed action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It denies delete access to the file server for requests from the 192.0.2.0/24 IP range

The policy explicitly denies delete actions for requests originating from the 192.0.2.0/24 IP range. This is achieved by using a Deny effect in the access control rule's Condition block with the SourceIp condition key. The policy does not affect other actions or IP ranges, so only delete access is denied for that specific CIDR block.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It denies delete access to the file server for requests from the 192.0.2.0/24 IP range

    Why this is correct

    The Deny effect overrides any allow, and the IpAddress condition scopes it to source addresses within 192.0.2.0/24. Delete actions on the file-server resource originating from that subnet are blocked, while requests from other ranges remain unaffected.

  • ✗

    It allows delete access to the file server for all IPs

    Why it's wrong here

    The Effect value is "Deny", not "Allow", and the Condition restricts SourceIp to 192.0.2.0/24, so delete is blocked for that range rather than permitted for every address. It is tempting because an Action of "delete" on file-server does appear in the rule.

  • ✗

    It allows read access to the file server from the IP range

    Why it's wrong here

    The Action is "delete", not read, and the Effect is "Deny", so the rule blocks deletion from 192.0.2.0/24 instead of granting read access. It is tempting because the SourceIp condition genuinely scopes the rule to that address range.

  • ✗

    It denies all actions to the file server

    Why it's wrong here

    The rule pairs Effect "Deny" with Action "delete", so only delete operations from 192.0.2.0/24 are blocked; read, write and other actions remain unaffected. It is tempting because a Deny effect feels sweeping, but the Action field narrows its scope to one verb.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.